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Abstract. We present a continuous- variable quantum key distribution 

ri . protocol combining a continuous but slightly non-Gaussian modulation 

^ l' together with a efhcient reverse reconciliation scheme. We establish the 

. K , security of this protocol against collective attacks which correspond to 

^ ■ a linear quantum channel. In particular, all Gaussian attacks are con- 

Cu ' sidered in our framework. We show that this protocol outperforms all 

^ , , known practical protocols, even taking into account finite size efi'ects. 

ff^ . 1 Introduction 

>: 

Q^ . Quantum key distribution (QKD) is a cryptographic primitive allowing 

*ys I two distant parties, Alice and Bob, to establish a secret key in an un- 

^^ ' trusted environment controlled by some eavesdropper, Eve [1]. One of 

V/^ ■ the great interests of QKD is that it can be implemented with present 

O I day technology, at least for reasonable distances. 

I I Whereas discrete- variable protocols, such as BB84 [2], are quite resis- 

H" ■ tant to losses (experiments over more than 200 km have been achieved 

• 1— I . [3] ) , continuous- variable protocols do not seem to display the same qual- 

r> I ity: the present experimental record is around 25 km [4,5], although re- 

C^ ■ cent theoretical results suggest than 100 km should be achievable [6,7]. 

On the other hand, continuous-variable (CV) QKD does not require spe- 
cific equipment such as single-photon counters and can be implemented 
with off-the-shelf telecom components. For this reason, it is of great im- 
portance to find the protocols with the highest resistance to losses. In this 
paper we introduce such a protocol. 

Before describing the new protocol, let us first recall the main ideas of 
CVQKD, and explain the origin of its sensitivity to losses. The basic idea 
is to encode information on continuous variables in phase space to perform 
QKD [8]. This can be achieved with coherent states: the information is 



simply encoded in their displacement vectors and can be recovered by Bob 
thanks to homodyne or heterodyne detection (homodyne corresponds to 
the case where one random quadrature is measured, heterodyne means 
that both quadratures are measured) . Two main categories of modulation 
have been considered in the literature: a continuous Gaussian modulation, 
which maximizes the mutual information I^b between Alice and Bob, and 
discrete modulations (mainly consisting of either 2 or 4 states) allowing 
for a simpler reconciliation procedure. In the case where the data are not 
postselected, both modulation schemes have been proved secure against 
collective attacks (Ref. [9,10,11] for a Gaussian modulation, and Ref. [6,7] 
for discrete modulations in the case where the quantum channel is linear) . 
Finally, thanks to a de Finetti theorem in infinite-dimensional Hilbert 
spaces, it is enough to consider collective attacks to prove the general 
security of a CVQKD scheme [12]. 

The typical outline of a CV QKD protocol is the following. Alice 
prepares N coherent states \qk + ipk) where qk and pk are real random 
variables following the appropriate probability distribution: qk,Pk can be 
either centered normal random variables or Bernoulli random variables 
depending on the modulation of the protocol. Bob measures each state 
with a homodyne or a heterodyne detection (in the first case, he needs 
to inform Alice of his choice of quadrature). At this point, Alice and Bob 
possess A^ (or 2A^) couples of correlated data (2;^,^^). These data are re- 
lated through: yk = txk + Zk where t is an unknown constant and Zk is a 
centered random variable with unknown variance o"^ . Alice and Bob then 
proceed with the parameter estimation procedure whose goal is to esti- 
mate both t and a'^ by publicly revealing part of their data [13,14]. Note 
that this estimation can never be perfect in practice. The remaining data 
{xkiVk) for k E {I,--- , n} are used to distill a secret key. This is done 
by first applying a reverse reconciliation technique [15] where Bob sends 
some side information to Alice to help her guess the value of (yi, • • • , y„). 
The side information is typically composed of continuous data, for in- 
stance the absolute value \yk\ of Bob's data, as well as of the syndrome of 
a linear error correcting code (for instance of a Low-density Parity-check 
(LDPC) code [16,17]). The reconciliation procedure is characterized by 
its efficiency (5 which is the ratio between the length of the bit-string Alice 
and Bob manage to agree on and the mutual information /(x; y) they ini- 
tially shared. Finally the privacy amplification allows them to transform 
this partially unsecure bit-string into a secret key of length I = nK where 
the asymptotic key rate K is given by: 

K = l3I{x;y)-x{y;E). (1) 



Taking into account finite size effects leads to a more complicated expres- 
sion which can be found elsewhere [18,13,14] (see also discussion below). 
The quantity xiu'i ^) refers to the Holevo information between the eaves- 
dropper and Bob's data. Note that the main contribution to finite size 
effects comes from the inaccuracy in the parameter estimation: one should 
indeed consider for xiv't^) the maximal value compatible with the esti- 
mation except for some small probability epE, say 10"^''. 



The main limitation in terms of range for CV QKD stems from the 
finite reconciliation efficiency, especially for a Gaussian modulation in 
the low signal-to-noise ratio (SNR) regime. Using a discrete quaternary 
modulation improves the performances significantly as one is now able to 
perform an efficient reconciliation, even for arbitrarily low SNR [6,7]. On 
the other hand, upper bounding the Holevo quantity is more challenging 
in this scenario, and tight bounds are only available when the modulation 
variance is small. The reason for it is that the bounds are obtained from 
an optimality property of Gaussian states [19,9], and that the four-state 
protocol is close to a Gaussian protocol for low modulation variance only 
(typically the optimal variance corresponds to sending coherent states 
with a mean photon number between 0.2 and 0.5). While this is perfectly 
fine in theory, it certainly makes the experimental implementation more 
challenging. 



In this paper, we introduce a new continuous-variable QKD proto- 
col combining an efficient reconciliation procedure and a much tighter 
bound on xiv]^)- This protocol outperforms all known practical CV 
QKD protocols, both in terms of rate and achievable range. It also allows 
for larger modulation variances, hence significantly simplifying the exper- 
imental implementation for long distances. We will establish the security 
of this protocol against linear attacks (for instance Gaussian attacks) 
in the asymptotic regime. By definition, a linear attack corresponds to 
any action of the eavesdropper compatible with a linear quantum chan- 
nel between Alice and Bob (see Appendix 4 for details concerning linear 
channels). The general case of collective attacks will be treated elsewhere 
[20]. In order to show the robustness of the protocol, we will also present 
its performances in a non-asymptotic regime, where the imperfect pa- 
rameter estimation is taken into account using the techniques described 
inrefs. [13,14]. 



2 A new modulation scheme 



Let us first say a few words concerning the reconciliation procedure. A 
necessary condition in order to achieve long distances is to be able to have 
an efficient reconciliation at low SNR. The main difficulty here lies in the 
fact that we need a reverse reconciliation. Indeed, the side information 
sent by Bob must help Alice without giving Eve any relevant information. 
The only schemes where side information seems to have these properties 
are the Gaussian modulation where side information describes rotations 
in M^ [21] and the binary and quaternary modulations where side infor- 
mation consists of the absolute value of Bob's measurement result [6]. 

In order to increase the secret key rate, one needs to find the best 
possible balance between a large value of f3I{x; y) and a small value of 
x{y\ E). From this perspective, the protocol with a Gaussian modulation 
and the four-state protocol appear to be at the two ends of the spectrum. 
A Gaussian modulation, on one hand, insures the lowest possible value 
for the upper bound on xiv'i E), but unfortunately, the quantity /3/(x; y) 
is also quite small, and one cannot distill secret keys over large distances 
with this protocol. The 4-state protocol, on the other hand, is designed 
specifically to maximize the quantity /3/(x; y) at the cost of increasing the 
provable upper-bound on xiu] E), which is a consequence of the fact that 
a quaternary modulation only roughly approximates a genuine Gaussian 
modulation for low modulation variances. 

The idea of the protocol presented here is to combine these two so- 
lutions to find a better trade-off. The modulation scheme now consists 
in generating points centered on an 7-dimensional sphere in R* (this is 
done by considering together 4 successive coherent states in phase space) . 
Then, using the same technique as in Ref. [21], one can reduce the recon- 
ciliation problem to the discrete case, which can be efficiently solved as 
in Ref. [6]. However, because the continuous modulation on a sphere in 
M^ approximates a Gaussian modulation quite accurately, the bound on 
xiv, E) becomes much tighter than for the four-state protocol. 

We now give a detailed description of our new protocol. Alice sends 
4A^ coherent states to Bob such that the coordinates of all quadruples 
{|a4fc),|a4fc+i),|a4fc+2),|a4fc+3)} for k £ {I,--- , A^} are drawn with the 
uniform probability on the seven-dimensional sphere of radius 2a in phase 



space^: 



S'^ = {(a4fc, a4fc+i, a4fc+2, "4/0+3) G C"^ such that 

|a4fcp + |a4A:+i|^ + |a4fc+2p + |a4fc+3p = 4a^}- (2) 

a is related to AHce's modulation variance Va through Va = I0? (ex- 
pressed in shot noise units). Then Bob proceeds with an heterodyne mea- 
surement (as in Ref. [22] for instance). Here, it is crucial that both quadra- 
tures are measured in order to use the property of Eq. 2. The parameter 
estimation procedure now consists in revealing N — n quadruples in order 
to estimate the parameters t and o"^ as before. Then, the reconciliation 
procedure is a mix between the reconciliation using the octonions pre- 
sented in Ref. [21] and the one described in Ref. [6] using the concatena- 
tion of good error correcting codes with a repetition code in order to be 
able to work at very low SNR. It goes at follows. Bob first puts together 
his n 8-dimensional real vectors y'^ = {y\, • ■ ■ , y|) and chooses randomly 
n 8-bit strings {u^, • • • , u|). These 8-bit strings are mapped on points on 

a hypercube in R^ with coordinates u'' = ((— l)"i "^ !^ , • • • , (— l)"i — 



2v^ ' ' V ; 2V2 ' 
where ||y'^||^ = (?/i)^ + ' • ' + {y%)'^ ■ He then computes the n rotations in M^ 
mapping y to u as described in Ref. [21] and sends them, together with 
the value of Hy**"!! to Alice on the authenticated classical channel. Alice 
applies the same n rotations to her data. At this point. Bob computes the 
syndrome of his 8n-bit string for a code C he and Alice agreed on before- 
hand and sends this syndrome to Alice. This syndrome defines a subset of 
the 8n-dimensional hypercube containing the point (u-*-,--- ,u"). If the 
code C is well chosen, with high probability, Alice recovers the value of 
(ttj^jul, • • • ,^n)- The efficiency of this procedure is the same as the one 
of the reconciliation of 4-state protocol. Alice and Bob can then proceed 
with privacy amplification to obtain their secret key. 

3 Performance and security of the protocol 

Our goal here is to evaluate the secret key rate K. The first term (31{x; y) 
is rather easy to estimate. Because of the specific reconciliation procedure, 
/3 is the same as for the discrete-modulation protocol, and can be assumed 
to be at least 0.8 for any SNR lower than 1 [6]. The mutual information 



* This can be done quite simply: Alice only needs to draw eight random variable with a 
normal probability distribution and then to normalize this eight dimensional vector 



so that it belongs to the sphere <S^ of radius 2a in ' 



between Alice and Bob corresponds to the capacity of a binary input 
additive white Gaussian noise channel, which is a function of the SNR. 

In order to upper bound x(2/; E), one needs to consider the entanglement- 
based version of the protocol. Such a "virtual entanglement" does not have 
to be implemented, but it is formally equivalent to the used prepare-and- 
measure protocol. In this version, Alice starts by preparing n bipartite 
states 



oo 



m=e-'-'Y.^^\^t), (3) 



fc=0 



where 



iV'fc) = — ^^ V] \ki,k2,k3,k4)\ki,k2,k3,k4, 

/ /^_I_Q\ ^ ^ 



, 3 ) T,iki=k 



and performs a POVM on the first half of her state which projects the 
second half on the coherent states with the right modulation. These co- 
herent states are then sent to Bob. The covariance matrices of this state 
\^) respectively before and after the transmission through a linear chan- 
nel of transmission T and excess noise £, are noted F^ ® I4 and F ^ I4 
with 



where Va = 2a^ is Alice's modulation variance in the Prepare and Mea- 
sure version of the protocol. The parameter Z characterizes the level of 
correlation in phase space between the two halves of the states. The max- 
imal value of Z compatible with quantum mechanics is obtained in the 

case of a two- mode squeezed state and reads .^tms = y ^J + ^Va- This 
is therefore the relevant value when considering the QKD protocol with a 
Gaussian modulation. In the case of the continuous-modulation protocol 
introduced here, one has [14]: 



z = k^^^E^C^. (4) 

fc=0 

The fact that Z < Zxms leads to an increase of the upper bound on 
x{y\E) one can derive from a Gaussian optimality argument. In par- 
ticular, the value of x(?/j E) one obtains corresponds to the value one 
would obtain for a Gaussian modulation protocol with a quantum chan- 
nel characterized by a transmission Tq = F/F ~ T, and an excess noise 
iG = Fi + {F - 1)Va - i+{F - 1)Va, where F = [Z^us/Zf. Since 
one has F ~ 1 for reasonable values of Va, the main effect of the non- 
Gaussian modulation is the equivalent excess noise A^ = {F — 1)Va- 



Figure 1 displays this equivalent excess noise in the case of the protocol 
presented here, as well as for the 4-state protocol introduced in [6]. In 
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Fig. 1. Equivalent excess noise due to the non-Gaussian modulation. Upper curve refers 
to the 4-state protocol [6] , lower curve to the new continuous-modulation protocol. An 
excess noise of one unit of shot noise corresponds to an entanglement-breaking channel, 
therefore no security is possible with such a level of noise. 



state-of-the-art implementation, the excess noise is typically less than a 
few percent of the shot noise. This gives a approximate limit for the value 
of the equivalent excess noise that is acceptable. In particular, for the 
4-state protocol, one needs to work with modulation variances below 0.5 
units of shot noise. On the contrary, it becomes possible to work with 
much higher variances in the case of our new protocol. 

This can be seen on Figure 2 where we display the asymptotic secret 
key rate for a distance of 50 km for the new protocol as well as for the 
4-state protocol as a function of Alice's modulation variance. The various 
parameters are chosen conservatively: a quantum efficiency of 60% and an 
excess noise of 0.01. Both plots correspond respectively to a reconciliation 
efficiency of 80% and a more optimistic value of 90%. The superiority of 
the new protocol is quite clear: the secret key rate is higher by nearly an 
order of magnitude, and one can work with significantly larger modulation 
variances. 

In order to confirm the robustness of the new protocol, we display 
on Fig. 3 the secret key rate when finite size effects are taken into ac- 
count. The secret key rate is computed against collective attacks, as de- 
tailed in Ref. [13]. Among various finite size effects [18], the most crucial 
ones for continuous-variable protocols are clearly the imperfect reconcil- 
iation efficiency (which prevents the protocol with a Gaussian modula- 
tion to achieve key distribution over large distances) and the parameter 
estimation. While the reconciliation efficiency is taken care of by the 8- 
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Fig. 2. Asymptotic secret key rate for tlie new protocol and tiie four-state protocol 
(heterodyne detection) for a distance of 50 km, as a function of Alice's modulation 
variance. The various parameters are an excess noise of 0.01 and quantum efficiency 
of the detectors is 77 = 60%. Reconciliation efficiency is supposed to be a conservative 
80% on the left Figure, and an optimistic 90% on the right Figure. 



dimensional continuous modulation, the parameter estimation is quite 
sensitive for continuous-variable protocols. In fact, the real problem lies 
in the estimation of the excess noise ^, which is very small compared to 
the shot noise, and thus hard to evaluate accurately. 




distance [km] 

Fig. 3. Non-asymptotic secret key rate for the new protocol, obtained for realistic 
values: excess noise ^ = 0.005, security parameter epE = 10"^", quantum efficiency of 
the detectors 77 — 60%, reconciliation efficiency 80% for the bi-AWGN channel. Half 
the samples are used for parameter estimation. From left to right, the block length is 
equal to 10^ 10^°, 10^^ and lO". 



In Fig. 3, all such finite size effects are taken into account [13]. The 
results are rather pessimistic, but remember that this is also true for 
all discrete- variable protocols [23], and our protocol performs relatively 
quite well. While exchanging 10^^ quantum signals is rather unrealistic, 



exchanging 10^ or even 10^" signals can be done with today's technology. 
Hence, our new protocol allows for the distribution of secret keys over 
distances of the order of 50 km, taking into account all finite-size effects. 

4 Perspectives 

As a conclusion, we presented a new continuous- variable QKD protocol 
based on a continuous but non-Gaussian modulation and established its 
security against collective attacks, provided that the quantum channel 
is linear. The use of a specific reconciliation procedure allows for the 
distribution of secrets keys over long distances, which was impossible 
with a Gaussian modulation. Moreover, this protocol clearly outperforms 
all known practical continuous-variable, with a secret key rate an order 
of magnitude higher than for the four-state protocol. 

An important question at that stage is how to avoid the extra hypoth- 
esis that the channel should be linear. As shown in Ref. [20], this can be 
done by using decoy states, in order to embed the non-Gaussian modu- 
lation into an overall gaussian modulation. It is then safe to evaluate the 
values of T and ^ from a gaussian probe beam, and then to use them as 
described in the present paper. 
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Appendix: linear quantum channels 

We shall define a linear quantum channel by the input-output relations 
of the quadrature operators in Heisenberg representation : 

Xout = gxXin + Bx 

Pout = gpPin + Bp (5) 

where the added noises Bx, Bp are uncorrelated with the input quadra- 
tures Xin, Pin- Such relations have been extensively used for instance in 
the context of Quantum Non-Demolition (QND) measurements of contin- 
uous variables [24], and they are closely related to the linearized approx- 
imation commonly used in quantum optics. Gaussian channels (channels 
that preserve the Gaussianity of the states) are usual examples of linear 
quantum channels. However, linear quantum channels may also be non- 
Gaussian, this will be the case for instance if the added noises Bx, Bp 
are non-Gaussian. 

For our purpose, the main advantage of a linear quantum channel 
is that it will be characterized by transmission coefficients Tx = Qx, 
Tp = Qp, and by the variances of the added noises Bx and Bp. These 
quantities can be determined even if the modulation used by Alice is 
non-Gaussian, with the same measured values as when the modulation is 
Gaussian (because these values are intrinsic properties of the channel). 
The relevant covariance matrix can then be easily determined, and Eve's 
information can be bounded by using the Gaussian optimality theorem. 



